Privacy
What Operenda accesses, why, how long we keep it, and what we never do with it.
What this is
Operenda is operated by Lukens Holdings, LLC.
Operenda gives a business a set of AI specialists that read its information, prepare work, and — where the business has explicitly permitted it — act on that business's behalf. To do that, the business connects accounts it already owns: email, calendar, social accounts, advertising accounts, payments.
This page describes exactly what we access, why, how long we keep it, and what we never do with it. It is written to be checked against the product rather than to be reassuring.
What we access, and why
Only what the business connects. Nothing is accessed until an owner connects an account, and each connection states in plain language what it grants before the consent screen appears.
Least privilege. We request read access only, until the business turns on a capability that genuinely requires more. A business that has never enabled outreach does not hold a send-mail permission.
Email, where connected: message contents, senders, recipients, subjects and attachments, so a specialist can decide what needs the owner's attention, file what does not, and draft replies. Calendar: events and attendees, to schedule around what is already booked. Social and advertising accounts: existing posts and performance figures, to learn the business's voice and report what worked. Payments: transaction and payout records, never card numbers.
We do not access anything the business has not connected, and we do not access personal accounts of individual staff.
Phone calls
A business can buy a phone number here, and its staff answer it. That is different from everything else on this page, because the person on the other end is not our customer and has not agreed to anything — so it is worth being exact.
What the caller is told. Nothing is hidden: the agent identifies itself as an automated assistant on any call it places, and it never claims to be a person on a call it answers.
What is kept. A written transcript of the call, its length, the number it came from, and a summary of what was wanted. The transcript is kept because it is the business's record of what was said to it — the same reason a business keeps its emails — and because the follow-up raised from a call has to be checkable against what was actually said.
What is not kept. We do not store call audio. A recording exists only fleetingly at the telephony and voice providers while the call is happening, and we do not retain one.
Who else sees it. A call passes through a telephony provider, which connects it, and a voice provider, which turns speech into words and back. Both are contracted processors acting on our instructions and neither may use what passes through for their own purposes. The words of the call are also sent to the model provider that decides what to say next, under the same terms as everything else on this page — including that none of it trains a general-purpose model.
Recognising a caller. If the number matches somebody already in the business's records, the agent is told who they are so it can greet them and pick up where things left off. It is also told, in the same breath, that a number proves nothing — so it may use what it knows to be helpful and never to disclose. It will not read out an address, a balance, or anything a previous call recorded, and if somebody says they are not that person it takes their word for it.
How long. Transcripts and call records follow the retention period the business sets, and are deleted when it expires. A business that sets no period keeps them until it deletes them or closes its account.
What we do with it
Connected-account data is used to do the work the business asked for, and for nothing else. Specifically, we do not:
— sell it, rent it, or share it with data brokers or advertisers;
— use it to train or fine-tune any general-purpose AI model, ours or a third party's;
— use it for advertising, profiling, or any purpose unrelated to running the business that connected it;
— allow our staff to read it, except where an administrator of that business asks us to investigate a specific problem, or where the law requires it.
Content is sent to our AI provider to generate the work. That provider processes it to return a result and does not retain it to train its models.
Where the human stays in control
By default, a specialist prepares work and stops. Sending an email, publishing publicly, or spending money each require the owner to approve them, one at a time.
An owner may permit some of those to happen without approval, but only through a deliberate confirmation that states in plain words what changes. Spending money is a separate permission with limits the owner sets, and it is never implied by any other setting.
Changes to accounts, permissions, integrations and billing can never be automated. There is no setting that allows it.
Every action a specialist takes — permitted, queued or refused — is written to a record the business can read and we do not edit.
How long we keep it
Working data — the contents of messages, events and records a specialist read to do a piece of work — is held only as long as needed to complete that work and to show the business what was done.
The business's own records inside Operenda — its tasks, documents, contacts, decisions and the audit trail — are kept while the account is open.
When a business disconnects an account, we stop accessing it immediately and delete the stored access credentials.
When a business closes its account, its data is deleted within 30 days, other than anything we are required to retain by law. An export can be requested before closing.
Security
Access credentials for connected accounts are encrypted at rest and held separately from business data. They are never written to logs and never shown in the interface.
Data is separated by business at the database level, enforced by row-level security, so one business cannot reach another's data.
Access to production systems is limited to named staff, requires multi-factor authentication, and is logged.
Your rights
A business may at any time: see what is connected and what each connection grants; disconnect an account; export its data; ask us to correct or delete information; and ask what has been accessed.
Individuals whose information appears in a business's records — its customers, suppliers and staff — may exercise their rights under applicable law by contacting that business, or us at the address below and we will pass it on.
Where required, we act as a processor on behalf of the business, which is the controller of its own records.
Google user data
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is used only to provide the features the business connected the account for. It is not transferred to others except as necessary to provide those features, to comply with the law, or as part of a merger or acquisition with notice. It is not used for advertising, and it is not used to train generalised AI models. No human reads it except with the business's explicit permission, to resolve a specific problem they reported, for security purposes, or where the law requires it.
Contact
Write to privacy@operenda.com. We answer within five working days.